Mozilla · Firefox · CVE-2018-12398
**Name of the Vulnerable Software and Affected Versions**
Firefox versions prior to 63
**Description**
The issue is related to the lack of input sanitization, allowing a remote attacker to bypass the Content Security Policy (CSP) mechanism. This can be achieved by injecting stylesheets through reflected URLs in certain resource URIs, such as 'chrome:'.
**Recommendations**
For versions prior to 63, update to version 63 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive resources to minimize the risk of CSP bypass.